Hi.
I need help on what to do with this.
windows host process (rundll32)
I think starting from about 2-3 weeks ago this wants access to the internet, I allowed the first ip it asked for as was logging again and again every 3 second strying really hard. I did of course also virus scan online and offline and clean.
I then checked the windows7firewallcontrol again and I see now 210658 attempts accessing the internet this time another microsoft ip. 65.55.162.27
What seems unusual is how frequent it is.
some log examples.
26/05/2011|03:47:06|IPv4 TCP 65.55.162.27:443(61705)|Windows host process (Rundll32)|Microsoft1 Outgoing|C:\windows\syswow64\rundll32.exe
26/05/2011|03:47:06|IPv4 TCP 65.55.162.27:443(61706)|Windows host process (Rundll32)|Microsoft1 Outgoing|C:\windows\syswow64\rundll32.exe
26/05/2011|03:47:06|IPv4 TCP 65.55.162.27:443(61707)|Windows host process (Rundll32)|Microsoft1 Outgoing|C:\windows\syswow64\rundll32.exe
26/05/2011|03:47:09|IPv4 TCP 65.55.162.27:443(61708)|Windows host process (Rundll32)|Microsoft1 Outgoing|C:\windows\syswow64\rundll32.exe
26/05/2011|03:47:09|IPv4 TCP 65.55.162.27:443(61709)|Windows host process (Rundll32)|Microsoft1 Outgoing|C:\windows\syswow64\rundll32.exe
26/05/2011|03:47:09|IPv4 TCP 65.55.162.27:443(61710)|Windows host process (Rundll32)|Microsoft1 Outgoing|C:\windows\syswow64\rundll32.exe
Is this legitimate and if yes what is suggestion for safe zone for this service?
